Privacy Policy
What this says, in short
This policy explains what North Star Nurse Delegation collects about you as a staff member or a website visitor, why, and who ever sees it. Client health records are not covered here — those are protected health information under HIPAA and our Notice of Privacy Practices. In short: we collect only what running the platform requires, we never sell data or run advertising, and everything you do on the platform is recorded in a permanent audit trail.
Who and what does this policy cover?
This policy is written by North Star Nurse Delegation, LLC, an Oregon nursing practice serving the Portland metropolitan area (Multnomah, Washington, and Clackamas counties). It covers two groups of people:
- Staff — nurses, administrators, and the owner who sign in to our platform. The platform is staff-only. Clients and families never sign in.
- Website visitors — anyone who browses nsndelegation.com without signing in, including anyone who sends us an enquiry from our referral page.
What this policy does not cover: client health information. The client records inside our platform are protected health information (PHI). They are governed by HIPAA, by Oregon law, and by our Notice of Privacy Practices — not by this document. If you are a client or a family member with a question about a client's health records, contact us directly and we will handle it under those rules.
Everyone who uses the platform is part of our workforce under HIPAA. Your obligations for handling client information come from HIPAA training and agency policy. This document is only about the information we hold about you.
What do we collect about staff?
If you work here and use the platform, we hold:
- Your name and work email address.
- The identifier Microsoft assigns your account (your Entra object ID) and the times you sign in.
- Your license and credential records.
- Your hours and payroll data.
- An audit trail of your actions: every sign-in, every record you open, and every change you make.
- When a signature is captured on your device, a client's at a visit or your own on a staff document: the device's network (IP) address, its browser, and, if you let the browser share it, where the device was at that moment. They are kept with the signature, and printed on its certificate, as evidence of how and where it was made.
We never see your password. Sign-in happens through Microsoft Entra ID, the agency's Microsoft 365 system. Your password goes to Microsoft, not to us, and we never receive or store it.
There is no self-service sign-up. An administrator creates every account, and only for people who work with the agency.
What do we collect about website visitors?
If you just visit nsndelegation.com, we collect almost nothing.
Our web server keeps the ordinary technical logs that any web server keeps — things like your IP address, the page you requested, and the date and time. We use those logs to keep the site running and to investigate problems or abuse.
Owner & counsel: confirm what AWS actually logs for the production site
If you send us an enquiry from our referral page, we keep what you type into it: your name, your role and organization, your phone number and email, the best time to reach you, the county, care setting and way of paying you chose, how many people you are asking about, how you heard about us, and your message. We keep it so we can call you back, and so we can tell which ways of finding us actually work. Only the agency's own staff read it: the office, and the nurses who take referrals. Please keep a client's health details out of the message; we will ask for what we need on the phone.
That is it. No advertising trackers, no third-party analytics, no marketing cookies. We do not follow you around the internet.
What do we use this information for?
We use staff information for four things:
- Running the platform. Your account and your sign-ins — the basics of giving you a working tool.
- Safety and accountability. The audit trail exists so we can always show who saw what and who changed what. In a nursing practice, that record protects clients, and it protects you.
- Payroll and credentialing. Your hours, your pay, and keeping your license and credential records current.
- Legal compliance. Meeting our obligations under Oregon nursing law, Medicaid program rules, HIPAA, and employment law.
We use visitor server logs only to operate and secure the website, and an enquiry only to answer it and to count how people found us.
What do we never do with your information?
Some things are simply off the table:
- We never sell your information. Not to anyone, not for anything.
- We never use your information for advertising, and we run no advertising.
- We never build behavioral profiles of you or make automated decisions about you without a person involved. Owner & counsel: confirm no fully automated decisions are made about staff anywhere in the platform — scheduling, payroll flags, or anything else — before this clause is published
- We never put third-party analytics or tracking scripts on the site or the platform.
How do the AI features handle information?
Some parts of the platform can draft text using AI — Microsoft's Azure AI models (Microsoft Foundry), behind entry points the owner configures and under the agency's business associate agreement with Microsoft. Three things hold for every one of them:
- Identifying fields never leave the record on their own. A client's name, date of birth, Medicaid ID, Social Security number, address, phone number, and email are never sent to the model from the fields where the record keeps them. This is enforced in the software, not left to habit: an entry point cannot be set up to send them.
- A document the model reads is sent whole. When a feature reads a scanned or photographed page, such as a medication list, a doctor's order or a referral form, the whole page goes to the model, and whatever is printed on it goes too. That is often the client's name and date of birth, and sometimes their Medicaid ID. It is sent under the same business associate agreement with Microsoft.
- A nurse reviews every AI draft before anything is kept. Nothing an AI writes goes into a record automatically. A person reads it, corrects it, and decides.
AI here is a drafting aid for the nurse, not a decision-maker about clients or about staff.
Who do we share information with?
A short list, and each entry has a reason:
- Microsoft. Runs our sign-in (Entra ID), our email and files (Microsoft 365), our calendar, and the AI drafting models described above (Azure AI Foundry, under our business associate agreement with Microsoft; they never receive a client's identifying fields from the record, and they do receive the whole of any document a feature reads). When the platform pushes a visit to an Outlook calendar, the event carries only the client's initials, the time, and the address — never a diagnosis or clinical detail.
- Amazon Web Services (AWS). Hosts the platform in its US West (Oregon) region, under a business associate agreement with the agency.
- Regulators and auditors, when the law requires it — for example, a licensing board, a Medicaid program audit, or a lawful government request.
- A successor, if the agency is ever sold, merged, or reorganized. Records would transfer as part of that lawful transaction, and we would require the transfer to be subject to this policy. We would tell staff before it happened. Owner & counsel: have counsel confirm the successor-transfer wording
We never share your information with data brokers, advertisers, or marketers, because we have nothing to do with any of them.
What does the site store in your browser?
The platform stores a small amount of functional state in your browser's local storage:
- Your theme and display density preferences.
- Drafts you have typed but not yet sent, so a dropped connection does not eat your work.
- Sign-in convenience state, so you are not asked to start over every time.
This stays on your device and exists only to make the platform work well for you. There are no marketing cookies and no tracking cookies — here or anywhere on our site.
How do we protect your information?
The main protections, in plain terms:
- Sign-in through Microsoft Entra ID, which supports multi-factor authentication. We never see your password.
- Accounts only by administrator. No one can create their own account; an administrator provisions each one, and access can be removed the same way.
- Encryption in transit. Traffic between your browser and the platform is encrypted.
- An append-only audit trail. Every sign-in, every record opened, and every change is recorded, and that record cannot be edited or quietly erased. Records are never hard-deleted in the ordinary course of business; corrections are made as addenda, so the original and the correction are both preserved.
No system is perfect, but this design means that if something goes wrong, we can see exactly what happened.
How long do we keep information?
Clinical records and the audit trail are kept for seven years from the end of a client's service. Because the audit trail is append-only, records of your account and your actions are part of it and are kept for that same period.
Employment records — your hours, payroll, and credential files — are kept for seven years after your employment ends, unless counsel advises a different period. Owner & counsel: confirm the retention period for employment and payroll records with counsel
An enquiry sent from our referral page is kept in the platform, with a note of how it was answered. Nothing deletes one automatically. Owner & counsel: how long an enquiry is kept, and in particular one that never became a client
Website-visitor server logs are kept only briefly, for security and troubleshooting. Owner & counsel: confirm how long AWS keeps the production site's server logs
Owner & counsel: what happens to records when a retention period ends — confirm the disposal practice with counsel
What are your privacy rights?
If you are an Oregon resident, the Oregon Consumer Privacy Act gives you rights over personal data: to know whether we hold data about you and what categories, to get a copy, to correct it, to delete it, and to opt out of targeted advertising, sale, and certain profiling. If we refuse a request, you can appeal our decision, and you can complain to the Oregon Attorney General.
One limit we must be upfront about: our records are append-only, and some are kept because clinical-records law and our audit obligations require it. Where the law requires us to keep something, we will decline a deletion request and tell you why.
An honest caveat: much of what we hold sits outside that law's scope. Health information covered by HIPAA is exempt from it, and so, largely, is information we hold about you in your role as a member of our workforce. We tell you this so the rights above do not promise more than the law delivers. That said, if you ask us about your information, we will answer plainly and work with you — whether or not a statute forces us to.
Two of the opt-outs are easy: we do not sell data and we do not do targeted advertising, so there is nothing to opt out of.
If you are a client or family member, your rights over client health records — to see them, get copies, and request amendments — come from HIPAA and are described in our Notice of Privacy Practices. Contact the agency directly at info@nsndelegation.com or 1-877-732-2631.
To exercise any right, use the contact details at the end of this policy. We will need to verify who you are before acting on a request.
What if you access the platform from the EEA or the UK?
We are an Oregon agency serving Oregon clients, and we do not expect European data protection law to apply to us. But if you ever access the platform from the European Economic Area or the United Kingdom — for example, as a remote contractor — we will honor the equivalent rights for you: access, correction, erasure where the law allows it, restriction, portability, and objection. Where clinical-records law or our audit obligations prevent erasure, we will tell you so and explain why.
Owner & counsel: confirm with counsel whether the GDPR or UK GDPR actually applies before any staff member or contractor works from the EEA or the UK
Is this site for children?
No. The website and the platform are not directed at anyone under 18. The platform is a workplace tool for licensed professionals and agency staff. We do not knowingly collect information from children, and if you believe we have, contact us and we will remove it wherever the law and our record-keeping obligations allow.
What happens when this policy changes?
We may update this policy as the platform, our vendors, or the law changes. When we do, we will post the new version on this page with the date it took effect.
If a change meaningfully affects how we handle staff information, we will tell staff directly — not just quietly update a web page.
How do you reach us?
For any question about this policy, or to make a privacy request:
- North Star Nurse Delegation, LLC — an Oregon company serving the Portland metropolitan area
- Phone: 1-877-732-2631
- Email: info@nsndelegation.com
- Website: nsndelegation.com
- Mailing address for legal notices: Owner & counsel: registered mailing address for legal notices
Privacy requests are answered by Owner & counsel: who answers privacy requests — name a role, not a person.
